WHAT'S NEW IN ALAMARTE ADMIN MENU
New features, functional improvements, and enhanced security
UPDATE OVERVIEW
Alamarte Admin Menu 1.2.0 delivers a complete functional and security review of the module. The update retains the technical identifier mod_alamarte_adminmenu, preserves existing configuration, and respects the published status and administrative assignments of the module.
NEW FEATURES
Expanded Administrative Selector
The Menu Item Link selector incorporates 61 official Joomla! destinations, organized into functional groups for easy location:
• Joomla!
• Content
• Menus
• Users
• Extensions
• Languages
• Contacts
• Banners
• Privacy
• Smart Search
The selector also retains published administrative items belonging to enabled extensions.
Each destination is checked using an allowlist and specific ACL permissions. A link configured by a Super User will not be displayed to another administrator who lacks permission to access the corresponding component or context.
Visual Validation for Manual Links
The Add Link field validates the address in real time and presents a visual status that is easy to interpret:
• Displays a spinner while the user types and during the AJAX check.
• Displays fa-check on a green background when the address is valid.
• Displays fa-times on a red background when the address is invalid.
• Displays an explanatory message below the field so the result does not rely solely on color or icon.
Validation begins 600 milliseconds after the last keystroke. When the user continues typing, previous requests are canceled to prevent outdated results or unnecessary checks.
Portable Path Normalization
Valid administrative addresses are automatically normalized to the following format:
administrator/index.php?option=com_example
The module supports:
• Relative administrative path.
• The same path with a leading slash.
• The full HTTPS URL of the same site.
• The exact domain without scheme, when matching the secure root provided by Joomla!.
The value is saved in a portable format to prevent the configuration from being permanently tied to a specific domain or location.
IMPROVED FEATURES
Single Destination and Clear Priority
Each custom link maintains a single operational destination:
• Menu Item Link: recommended option and takes priority.
• Add Link: used only when the selector is empty.
A manual address cannot block, replace, or invalidate a secure destination that has already been selected.
Integrated Themes with Atum
Auto, Light, and Dark modes utilize official variables from the Atum administrative template to control backgrounds, text, borders, hover states, and focus states.
The following issues were also resolved:
• Inconsistent active states.
• Stale preferences stored in the browser.
• Contrast issues in Light mode.
• Incorrect default theme selection.
Custom Paths and Titles
Resolved issues related to:
• Double escaping of parameters in addresses.
• Joomla! installations located in subfolders.
• Duplicate path construction /administrator/administrator.
• Width and spacing of long custom titles.
• Multiline wrapping during hover and focus states.
Enhanced Help for Beginners
Custom link fields include detailed explanations in Spanish and English regarding:
• How to add, remove, and reorder records.
• Which destination type takes priority.
• Which path formats are allowed.
• Why an address might be rejected.
• How user permissions work.
• What happens when a field is left blank.
SECURITY AND RELIABILITY
Version 1.2.0 incorporates an in-depth security review of controls related to links, AJAX, permissions, and the installer:
• Mandatory PHP validation before saving and rendering any link.
• AJAX endpoint restricted to backend-authenticated users.
• AJAX requests permitted via POST method only.
• Mandatory Joomla! CSRF token check.
• ACL permission verification on com_modules.
• Confirmation that the received ID belongs to a real instance of Alamarte Admin Menu.
• Same-origin and request content-type verification.
• Input and response size limits.
• Timeout limits to complete validation.
• Strict JSON structure validation.
• Prepared statements using bound parameters.
• Initial installer operations wrapped in a database transaction.
• Contextual escaping of titles, URLs, targets, icons, and language strings.
The module explicitly rejects:
• External domains.
• Insecure HTTP addresses.
• Credentials embedded inside URLs.
• Frontend paths.
• URL fragments.
• Directory traversal attempts.
• Duplicate keys.
• Array-formatted parameters.
• Parameters flagged as sensitive or insecure.
Downgrade prevention is maintained, and Joomla! 5.0 and PHP 8.1 are enforced as minimum installation requirements.
DISTRIBUTION INTEGRITY
The package includes MD5 and SHA-256 checksum files allowing verification that installed files match the official release binary.
UPGRADE COMPATIBILITY
Updating to Alamarte Admin Menu 1.2.0 preserves:
• Configured parameters.
• Existing custom links.
• Module published status.
• Administrative assignments.
• Technical identity mod_alamarte_adminmenu.
No custom database tables are created, and zero external dependencies are added.
VERSION 1.2.0 • NEW FEATURES • REAL-TIME VALIDATION • ENHANCED SECURITY

ES
EN 



